9.8
CVE-2024-41702 - SiberianCMS – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje…
SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
5.3
CVE-2024-41701 - AccuPOS – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
7.5
CVE-2024-41696 - Priority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Informatio…
Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
7.5
CVE-2024-41695 - Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory
Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory
5.3
CVE-2024-41694 - Cybonet – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
6.9
CVE-2024-7226 - SourceCodester Medicine Tracker System Password Change cross-site request forgery
A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user of the component Password Change Handler. The manipulation leads to cross-site request forgery. The attack…
5.5
CVE-2024-38432 - Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
5.3
CVE-2024-38431 - Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
5.4
CVE-2024-38430 - Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting…
Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
7.2
CVE-2024-41924 -
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may…